For IndividualsFor Educators
ExpertMinds LogoExpertMinds
ExpertMinds

Ace your certifications with Practice Exams and AI assistance.

  • Browse Exams
  • For Educators
  • Blog
  • Privacy Policy
  • Terms of Service
  • Cookie Policy
  • Support
  • AWS SAA Exam Prep
  • PMI PMP Exam Prep
  • CPA Exam Prep
  • GCP PCA Exam Prep

© 2026 TinyHive Labs. Company number 16262776.

    PracticeAWS Solutions Architect Professional (SAP-C02)AWS Solutions Architect Professional SAP-C02 Practice Exam 6Question 18
    Medium1 markMultiple Choice
    Domain 1.4: Multi-Account EnvironmentMulti-AccountCloudTrailLogging

    AWS SAP-C02 · Question 18 · Domain 1.4: Multi-Account Environment

    A company has 100 AWS accounts. They want to centralize all AWS CloudTrail logs into a single S3 bucket in a dedicated Log Archive account. The solution must ensure that member accounts cannot modify or delete the logs. What is the BEST approach?

    Answer options:

    A.

    Create a CloudTrail trail in each member account and configure cross-account delivery to the S3 bucket.

    B.

    Create an Organization trail in the management account. Configure it to deliver logs to an S3 bucket in the Log Archive account.

    C.

    Use AWS Config aggregator to collect CloudTrail logs centrally.

    D.

    Deploy a Lambda function in each account to forward CloudWatch Logs to the central S3 bucket.

    How to approach this question

    Identify the native Organizations feature for centralized logging.

    Full Answer

    B.Create an Organization trail in the management account. Configure it to deliver logs to an S3 bucket in the Log Archive account.✓ Correct
    Create an Organization trail in the management account. Configure it to deliver logs to an S3 bucket in the Log Archive account.
    An Organization trail logs all events for all AWS accounts in the organization. Member accounts cannot modify or delete this trail.

    Common mistakes

    Setting up individual trails, which is hard to manage at scale.
    Question 17All questionsQuestion 19

    Practice the full AWS Solutions Architect Professional SAP-C02 Practice Exam 6

    75 questions · hints · full answers · grading

    Sign up freeTake the exam

    More questions from this exam

    Q01A global enterprise requires highly available hybrid connectivity between its on-premises data ce...HardQ02An organization has 50 VPCs across two AWS Regions connected via Transit Gateways (TGW). The TGWs...HardQ03A company uses AWS Organizations. The network team wants to share a central Transit Gateway (TGW)...MediumQ04An enterprise has on-premises data centers in the US and Europe. They want to use the AWS global ...HardQ05A company requires that all API calls to Amazon S3 from their VPC must not traverse the public in...Medium
    View all 75 questions →